Security, privacy and compliance — verified.
Safeguarding patient data is non‑negotiable. ClinixSummary employs industry‑standard encryption, strict access controls and immediate audio deletion — governed by the ClinixQM Quality Management System — to give you confidence that your practice and your patients are protected.
Registered with the MHRA. UKCA marked.
ClinixSummary is registered with the UK Medicines and Healthcare products Regulatory Agency (MHRA) as a Class I medical device and carries UKCA marking. Clinical documentation software that meets the regulatory bar your practice is held to.
MHRA registration
Registered as a medical device with the UK regulator, with the obligations that registration carries — vigilance, traceability and post‑market surveillance.
UKCA marking
The UKCA mark declares conformity with the UK Medical Devices Regulations for a Class I device — covering safety, performance and labelling requirements.
Governed by ClinixQM
Our quality management system underpins the registration — documented processes for risk, change control, incident handling and continuous improvement.
End‑to‑end encryption
All data is encrypted in transit using TLS 1.2+ and encrypted at rest with AES‑256. These bank‑grade standards ensure that voice recordings, transcripts and metadata remain confidential at all times.
Ephemeral audio & data control
We never store audio recordings. Once your note is generated, recordings are immediately and permanently deleted. You remain in control of your transcripts, which you can remove at any time.
HIPAA & GDPR compliance
ClinixSummary meets the requirements of HIPAA, GDPR, PIPEDA/PHIPA, CCPA and other global privacy regulations. We sign Business Associate Agreements (BAAs) and maintain full regulatory alignment.
De-identified training data
Our models are fine‑tuned on anonymised, de-identified, non‑PHI data and run inference on secure infrastructure. We never use your transcripts to train customer‑facing models.
Penetration testing
Regular third‑party penetration tests and vulnerability assessments are conducted against our infrastructure and applications. Findings are triaged, remediated and re‑tested on a continuous basis.
Incident response
A documented incident response plan ensures breach notification within 72 hours as required by GDPR. 24/7 monitoring, alerting and defined escalation playbooks keep response times minimal.
Clinix QM: Quality at every layer.
The ClinixQM Quality Management Process generates outputs that meet clinical standards through systematic review, feedback loops, and continuous improvement protocols.
Clinical QA Reviews
Dedicated quality assurance team conducts regular manual reviews of model outputs against clinical documentation standards, ensuring accuracy and completeness.
Role-Based Access Controls
Fine-grained permission systems ensure that only authorised personnel can access patient data, with full audit trails for every action taken in the system.
Compliance Certifications
Ongoing certification processes and third-party audits ensure ClinixSummary meets and exceeds healthcare industry security and compliance benchmarks.
Our vendors, disclosed.
We believe in full transparency about the third parties that help us deliver our service. Every sub-processor is bound by data protection obligations no less protective than our own. We provide at least 30 days' written notice before engaging a new sub-processor.
| Sub-Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Transcript and speech inference for clinical context | De-identified clinical text | USA | |
| Security & live system monitoring | System logs & operational telemetry (no PHI) | USA | |
| Cloud infrastructure | Encrypted clinical data | Multi-region | |
| Cloud infrastructure, AI services & speech-to-text | Encrypted clinical data | Multi-region | |
| Payment processing | Billing data (no PHI) | USA | |
| Transactional email delivery | Email addresses, notifications (no PHI) | USA | |
| iOS app distribution | App metadata, user account | USA | |
| Android app distribution | App metadata, user account | USA | |
| SSL/TLS certificate authority | Domain validation data | USA / UK | |
| Email authentication monitoring | Domain & email auth reports (no PHI) | USA |
This list is maintained as part of our Data Processing Agreement. We provide at least 30 days' prior written notice before engaging a new sub-processor.
Security is a culture, not just a feature.
Employee Security
All team members undergo background checks and mandatory security awareness training. Access follows the principle of least privilege and is reviewed regularly.
Vendor Management
Every sub-processor undergoes due diligence review before engagement. Contractual data protection obligations, regular reassessment and right-to-audit clauses are standard.
Business Continuity
Disaster recovery plans, encrypted backups and uptime monitoring ensure service availability. Infrastructure spans multiple regions for geographic redundancy.
Everything you need for due diligence.
Privacy Policy
How we collect, use and protect your data.
Your Privacy Choices
Manage consent, data access and deletion requests.
Terms of Service
Standard terms governing platform usage.
Usage Policy
Acceptable use guidelines and restrictions.
Security & Compliance Whitepaper
Technical security specification (PDF).
QMS Whitepaper
Quality management system methodology (PDF).
Architecture Overview
System architecture and infrastructure design (PDF).
Immediate deletion & granular control.
Audio retention
Deleted after note generation
Transcript storage
Short retention / user‑controlled
User deletion
Export & permanent erase at any time
Audit trails
Full activity logs for governance
Patient privacy notice for your practice.
Download our printable patient privacy leaflet to display in your waiting room or consultation area. It explains how AI documentation works, what happens to the recording, and reassures patients about their privacy.
Patient Privacy Notice — Printable Leaflet
Available in 6 languages. Designed for clinic walls and waiting rooms.